Comment 9 for bug 1796563

Revision history for this message
Tim Donohue (tdonohue) wrote :

For what it's worth, we ran into this issue today as well. It looks like the related Ghostscript vulnerability is detailed here: https://www.kb.cert.org/vuls/id/332928

While the release notes are not exactly *clear*, Ghostscript v9.25 seems to make reference to fixing some vulnerabilities of this sort: https://www.ghostscript.com/doc/9.25/News.htm

Just adding in this information in case it's helpful to others encountering this. I admit, I have no verification that Ghostscript v9.25 fixes the vulnerability. So, only comment out these new ImageMagick configurations at your own risk.